ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow Attestation

ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow Attestation
复制标题

DOI:
10.48550/arxiv.2303.16282
复制
发表时间:
2023-03
期刊:
ArXiv
影响因子:
--
通讯作者:
Adam Caulfield;Norrathep Rattanavipanon;I. O. Nunes
Adam Caulfield;Norrathep Rattanavipanon;I. O. Nunes
中科院分区:
其他
文献类型:
--
作者:
Adam Caulfield;Norrathep Rattanavipanon;I. O. Nunes

文献摘要

相似文献

低端嵌入式设备越来越多地用于各种智能应用程序和空间。它们是在严格的成本和能源预算下使用的微控制器单元(MCU)实施的,该单元缺乏通用处理器中可用的安全功能。在这种情况下,提出了远程证明(RA)作为廉价的安全服务,以使验证者(VRF)能够远程检测到在低端供体MCU(PRV)上安装的软件二进制二进制的非法修改。由于劫持软件控制流的攻击可以逃避RA,因此控制流量证明(CFA)增加了RA,并提供有关执行二进制指令的确切顺序的信息,从而可以检测控制流量攻击。我们观察到,当前的CFA体系结构不能保证VRF在发生攻击时曾经收到控制流报告。反过来,当他们支持利用检测时,他们没有提供指出漏洞原点的方法。此外,现有的CFA需要二进制仪器,会产生大量的运行时开销和代码尺寸增加,或者相对昂贵的硬件支持,例如哈希引擎。此外,当前的技术既不是连续的(仅是为了证明独立的操作),也不是主动的(没有提供安全的手段来远程补救检测到的妥协)。为了共同解决这些挑战,我们提出了ACFA:用于活动CFA的混合(硬件/软件)体系结构。 ACFA可以连续监视MCU中所有控制流动传输,并且不需要二元仪器。它还利用最近提出的主动根源的概念,可以在检测到妥协时对漏洞来源进行安全审核并保证补救。我们在商品低端MCU(TI MSP430)之上提供了ACFA的开源参考实施,并对其进行评估以证明其安全性和成本效益。
Low-end embedded devices are increasingly used in various smart applications and spaces. They are implemented under strict cost and energy budgets, using microcontroller units (MCUs) that lack security features available in general-purpose processors. In this context, Remote Attestation (RA) was proposed as an inexpensive security service to enable a verifier (Vrf) to remotely detect illegal modifications to a software binary installed on a low-end prover MCU (Prv). Since attacks that hijack the software's control flow can evade RA, Control Flow Attestation (CFA) augments RA with information about the exact order in which instructions in the binary are executed, enabling detection of control flow attacks. We observe that current CFA architectures can not guarantee that Vrf ever receives control flow reports in case of attacks. In turn, while they support exploit detection, they provide no means to pinpoint the exploit origin. Furthermore, existing CFA requires either binary instrumentation, incurring significant runtime overhead and code size increase, or relatively expensive hardware support, such as hash engines. In addition, current techniques are neither continuous (only meant to attest self-contained operations) nor active (offer no secure means to remotely remediate detected compromises). To jointly address these challenges, we propose ACFA: a hybrid (hardware/software) architecture for Active CFA. ACFA enables continuous monitoring of all control flow transfers in the MCU and does not require binary instrumentation. It also leverages the recently proposed concept of Active Roots-of-Trust to enable secure auditing of vulnerability sources and guaranteed remediation when a compromise is detected. We provide an open-source reference implementation of ACFA on top of a commodity low-end MCU (TI MSP430) and evaluate it to demonstrate its security and cost-effectiveness.